on ‎2019 Aug 27 8:50 AM
All,
As a part of completing our migration on SAP production kernel, we are executing multiple T-Codes (e.g. FB41 - Tax) which are critical and have wider access assigned to Functional Accounts in the prod kernel. The access control teams are mentioning that assigning multiple T-codes to one functional account may result in a Segregation of Duties (SOD) or compliance issue. In order to avoid this, we need to create multiple Functional IDs, but we do not have that many users who can perform these actions in the kernel. The access teams say that "it is not possible to create multiple Functional ID for a user for the missing authorizations, its an compliance issue".
As a compliance person, I would like to know if there is any solution for the above scenario which can help the team in executing different T-codes using functional accounts without causing SOD/Compliance issue.
Let me know if the above information and question is clear, if not I will provide the information as required. Thanks in advance for your time to read this post and providing your valuable inputs.
Thanks,
ragav_in
Request clarification before answering.
The proper solution to segregation of duties issues is, of course, to have enough people so that no one person has access to combinations of functions that they shouldn't. Creating multiple accounts for a single person doesn't do that. It might make the system happy and stop it reporting SoD issues as it doesn't know the accounts are used by the same person, but you do still have one person with access to conflicting functions.
If you simply don't have enough people, then you need to look at creating mitigating controls. These are, for example, reports that get run by somebody else, to check that somebody with conflicting access has never done anything they shouldn't. GRC can monitor, and even automate, these mitigating controls so that you can be sure they aren't being neglected.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 17 | |
| 8 | |
| 6 | |
| 6 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.